HNHacker News
TopNewBestAskShowJobs

technonerd

322 karma · joined February 27, 2015

submissionscomments
technonerd··on The deadly rise of giant trucks and SUVs
No mention of the 1964 chicken tax either.
technonerd··on SoundCloud has banned VPN access
Soundcloud got breached

>However, the company's response included a configuration change that disrupted VPN connectivity to the site. SoundCloud has not provided a timeline for when VPN access will be fully restored.

https://www.bleepingcomputer.com/news/security/soundcloud-co...

technonerd··on Nightclub stickers over smartphone rule divides the dancefloor
I attend a few parties that preach/practice this. Along with it being everyones responsibility to enforce a no cellphones policy on the dance floor. It provides for a much better experience on the dance floor. Just be yourself ;) Live in the NOW. I think some guy named Danny Tenaglia mentioned that once. The curators of these events have also built wall of sounds around the world(life changing BTW) and care about the music.

Education about a proper CLUB/PARTY night goes a long ways.

technonerd··on How Aphex Twin Made Selected Ambient Works 85-92
Everyone seemed to be influenced by AFX in the 90s? Or at least it was the in thing Todo, make ambient techno. Digging through the back catalog of techno artist you seem to find LOTS of 90s ambient / IDMish techno that are beautiful pieces of music. Speedy J's ginger and gspot albums and Luke Slater's the 7th plain albums come to mind for 90s ambient but now they are playing mind bending techno.
technonerd··on Undetectable very-low frequency sound increases dancing at a live concert
2nd year throwing the party they setup a nice stack of hay bales near the back of the dance floor. And then bought a double wide trailer and parked that to right of the stage, the camp site is also on that side.
technonerd··on Undetectable very-low frequency sound increases dancing at a live concert
If you throw a party in the middle of a corn field and the town next over not the town the party is in has noise complaints, you're not having fun.

God bless the turbo soundsystem at the great beyond festival.

technonerd··on NASA’s Webb takes star-filled portrait of Pillars of Creation
Handy Dandy Slider action between the two!

https://esawebb.org/images/comparisons/weic2216/

technonerd··on Twitch finally takes action against gambling
It's been a interesting past couple of days of drama but the article fails to mention that twitch employees were accepting large amounts of money from gambling streamers live on stream.

https://twitter.com/ostonox/status/1572264800616599552

https://nitter.rawbit.ninja/ostonox/status/15722648006165995...

technonerd··on Ask HN: How do you discover music?
I never really liked exploring music on Spotify the back catalog was non existent for DJs putting out amazing stuff in the 90s and 00s. You get like 2010 all the way to current year. Worthless.
technonerd··on Ask HN: How do you discover music?
Adding STOOR's SHS series to that list, it was absolutely insane. All live on hardware and mixing over the internet in 2 locations.

Speedy J and Luke Slater https://www.youtube.com/watch?v=gVbQrn5BoA4

technonerd··on Ask HN: How do you discover music?
I frantically smash the Shazam button over and over again while I loop a certain part in a live DJ set on SoundCloud. When the DJ is overlaying 2 tracks at a faster bpm, adding their own basslines and AFX, Shazam rarely works. But when it does it's like finding a diamond in the rough. Then I listen to the EP it's on A and B sides, listen to other EPs from the DJ and listen to other releases on that label. Combination of SoundCloud, discogs, mixesdb.com, bandcamp and YouTube.

Lots of times the first comment will be a partial track list or I'll look up the tracklisting on mixesdb.

In the 90s to discover music it was you had to attend shows and crate dig or even call up the record label (long distance number!) and listen to the latest release over POTS.

technonerd··on Tinder turns 10: what have we learned from a decade of dating apps?
The past 3 times I have tried to use tinder, I was left thinking it's just a front for onlyfans, sex workers and scammers. Profiles would either have 'onlyfans $name' or 'of $name' or 'I don't use this app much here's my Instagram'. But when you opened up their insta profile first line in their about me section was a onlyfans link. Sprinkle in some gift card scammers, sex workers, not being good looking and huge anxiety problems and I was left disappointed and frustrated every time. If I reported profiles it would just show them later on and not block them. So I would always report them again and again.

I would always play along with the scammers. Mostly out of curiosity and bordem. I would practice my osint skills. And try to report domains for abuse.

technonerd··on Bibliogram, Open-source front-end for Instagram, is being discontinued
I ran into the private profile problem with bibliogram ALL THE TIME. Even tho I was friends with them on instagram. So I just stop using it. It was broken most of the time anyways. It was a fun 3rd party unoffical API frontend that I added to my list of other ones I could self host.

That amount of hostility to scrapping and 3rd party clients feels like that they want to be in control of the data not you.

technonerd··on Large scale Internet SSH brute force attacks seem to have stopped here
I have found nginx bad bot blocker [1] very handy for this. I have it setup to respond with 444 and it allows me to add my own rules very easily.

https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blo...

technonerd··on Large scale Internet SSH brute force attacks seem to have stopped here
I found disabling aes ciphers alone killed 90% of the bots with an occasional ECC only bot sneaking through. I only have 2-3 options for MAC, KEX and cipher. Certain mobile clients won't work (older embedded ssh library) but others support more modern configs. But I started my journey with [1] and have slowly tweaked and slimmed it down over the years.

https://stribika.github.io/2015/01/04/secure-secure-shell.ht...

technonerd··on Rufus: Microsoft is blocking Windows ISO downloads
https://github.com/pbatard/Fido/issues/41 and https://github.com/pbatard/Fido/pull/42
technonerd··on Niantic undergoes layoffs, cancels four games
pogo did a good job at killing ingress. Then niantic was like oops we forgot about you because you are the bastard child pokemon go is the gifted child. Lets rewrite the client from scratch but completely butcher it from both a UI and UX. Haven't touched it since they forced everyone to the prime client. I was heavily involved in both the local and national scene.

They also made the larger events (anomalies) paid entry, it was free before.

technonerd··on Permissive forwarding rule leads to unintentional exposure of containers (2021)
Security is an afterthought in docker, deploy first questions later the dirty harry way. I learned lots about dockers lack of defense while trying to harden my instances and questioned why some of the options weren't enabled by default (--cap-drop=all and --security-opt=no-new-privileges and userns remap) other than exposing bad dockerfiles practices.
technonerd··on Four Tet wins royalty battle over streaming music
dvs1 started a genius idea to help pay artist [1]. All the DJ has to do is import his playlist and enter the amount they want to share with the artist that were played in a given set. Not only is this man an absolute master behind the decks like you need to add him to your bucket list to see him hes that good. The dude reeks in passion for music and it shows in his DJ skills, it shows in the sound systems and warehouse he built. But he is also out there trying to help improve the scene.

[1] https://aslice.com/

technonerd··on Beanstalk Farms stablecoin project loses $182M to exploit
The anonymity set of tornado cant be that good can it? With all these major hacks dumping their eth into it.
technonerd··on A Bitcoin bust that took down the web’s biggest child abuse site
>He right-clicked on the page and chose “View page source” from the resulting menu.

>...

>He spotted what he was looking for almost instantly: an IP address. In fact, to Gambaryan’s

>surprise, every thumbnail image on the site seemed to display, within the site’s HTML, the IP >address of the server where it was physically hosted: 121.185.153.64.

That is indeed an opsec failure, along with using that same IP on an exchange. Which later turns out to be a computer aka the abuse website in the guys apartment.

technonerd··on Nvidia Hit by Major Cyberattack
https://twitter.com/vxunderground/status/1497484483494354946

LAPSU$ extortion group, a group operating out of South America, claim to have breached NVIDIA and exfiltrated over 1TB of proprietary data.

LAPSU$ claims NVIDIA performed a hack back and states NVIDIA has successfully* ransomed their machines.

technonerd··on Alternative privacy-respecting front ends for popular services
teddit loading slow is a known problem, it loads everything on the backend before sending to the user.

https://codeberg.org/teddit/teddit/issues/248

technonerd··on Alternative privacy-respecting front ends for popular services
rimgu is another one that popped up around the same time imgbin started commits. Supports a little bit more out of the box, galleries with comments and albums. But the both are VERY new projects

https://codeberg.org/3np/rimgu

technonerd··on U.S. insurrectionists received $500k in bitcoins from French donor
Dangerous to use if you're not careful. I guess that is one of the many downfalls of not having secure defaults. Taproot and Schnorr are slowly coming to bitcoin. But would this blog post even exist if they had used a coinjoin/payjoin or lightning?
technonerd··on More Than 70 West Point Cadets Accused of Cheating in Academic Scandal
I 'cheated' on all my Air Force tests, D: all of the above and whatever answer that was longest. Like you could just skim the answers and select the longest one and move onto the next one without reading the question. What a horrible way to teach someone.
technonerd··on 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
https://del.dog/sourcestatements.txt

source: They have a server hosted online by Akami CDN that wasn't properly secure. After an internet wide nmap scan I found my target port open and went through a list of 370 possible servers based on details that nmap provided with an NSE script.

source: I used a python script I made to probe different aspects of the server including username defaults and unsecure file/folder access.

source: The folders were just lying open if you could guess the name of one. Then when you were in the folder you could go back to root and just click into the other folders that you didn't know the name of.

deletescape: holy shit that's incredibly funny

source: Best of all, due to another misconfiguration, I could masqurade as any of their employees or make my own user.

deletescape: LOL

source: Another funny thing is that on the zip files you may find password protected. Most of them use the password Intel123 or a lowercase intel123 source: Security at it's finest.

technonerd··on American darknet vendor and Costa Rican pharmacist charged
There's so many questions left unanswered from this indictment. How did they get his emails, how did they get the bitcoin amount. I'm more interested in the details and opsec failures.
technonerd··on Key Change
It was most def a non-prime match (VAC enabled). They are a complete shit show and deter new players from lasting long in a free to play game.
technonerd··on Cloudflare Network Performance Issues
Ahh the "we test in prod" method
Page 1 of 2Next →